@bitwarden/cli 2026.4.0 hijacked via Checkmarx GitHub Actions breach
TeamPCP pushed a malicious @bitwarden/cli@2026.4.0 to npm between 17:57 and 19:30 ET on April 22, exploiting Bitwarden's use of the breached checkmarx/ast-github-action. bw_setup.js fetched Bun 1.3.13 from GitHub and ran a payload that targeted SSH, Git, npm, AWS/GCP/Azure, GitHub Actions secrets, and AI/MCP configs (.claude.json, .kiro/settings/mcp.json), exfiltrating via audit.checkmarx.cx. Live ~90 minutes; Bitwarden confirmed no end-user vault data was accessed.
Versions named here: 2026.4.0